-
-
Notifications
You must be signed in to change notification settings - Fork 402
Rule 942-APPLICATION-ATTACK-SQLI (id: 942360) contain false positive #3914
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
Hi @abudawud, Thanks for reporting this. Can you kindly provide more details, like error logs and modsec_audit logs. You should hide sensitive info ip addresses, domain names etc. From what I see the offending regex seems to be this: coreruleset/regex-assembly/942360.ra Line 49 in 227ba36
|
Hi @Xhoenix I think all log already available at crs sandbox CRS Sandbox |
I need the logs of actual request that created the FP to be able to help you, as you can understand anybody can read the regex and create an intentional FP, just saying. Kindly provide your error and modsec_audit logs, and I'll be able to create a rule exclusion for you. |
To help move things along here, this is what can be observed at PL 2:
|
It's probably the presence of the word |
It looks the the offending pattern is this sub-pattern from
It's quite specific, but maybe we could rethink the rule/patterns. The rule would also match against, for example, the following strings:
The rule requires the string to start with either non-word characters or digits, followed by spaces. So, this will not match strings like "Next create the file". A rule exclusion would also be an acceptable answer, here, I think. |
Description
Hi, i'm so sorry for the issue that i have been reported.
Many thanks for CRS team for this awesome WAF Rule.
I think a request:
1. update your apps
must not match rule id 942360is there any way to patch the signature of the rule ?
How to reproduce the misbehavior (-> curl call)
https://sandbox.coreruleset.org/?q=1.%20update%20your%20apps
Logs
Your Environment
CRS Sandbox environtment
Confirmation
[x] I have removed any personal data (email addresses, IP addresses,
passwords, domain names) from any logs posted.
The text was updated successfully, but these errors were encountered: